Repository logo
Log In(current)
  1. Home
  2. Colleges & Schools
  3. Graduate School
  4. Masters Theses
  5. The Maestro Attack: Orchestrating Malicious Flows with BGP
Details

The Maestro Attack: Orchestrating Malicious Flows with BGP

Date Issued
May 1, 2019
Author(s)
McDaniel, Benjamin Tyler  
Advisor(s)
Maxfield Schuchard
Additional Advisor(s)
Scott Routi
Bruce Maclennan
Permanent URI
https://trace.tennessee.edu/handle/20.500.14382/42392
Abstract

We present the Maestro Attack, a Link Flooding Attack (LFA) that leverages Border Gateway Protocol (BGP) engineering techniques to improve the flow density of botnet-sourced Distributed Denial of Service (DDoS) on transit links. Specific-prefix routes poisoned for certain Autonomous Systems (ASes) are advertised by a compromised network operator to channel bot-to-bot ows over a target link. Publicly available AS relationship data feeds a greedy heuristic that iteratively builds a poison set of ASes to perform the attack. Given a compromised BGP speaker with advantageous positioning relative to the target link in the Internet topology, an adversary can expect to enhance flow density by more than 30 percent. For a large botnet (e.g., Mirai), the bottom line result is augmenting the DDoS by more than a million additional infected hosts. Interestingly, the size of the adversary-controlled AS plays little role in this effect; attacks on large core links can be effected by small, resource-limited ASes. Link vulnerability is evaluated across several metrics, including BGP betweenness and botnet flow density, and we assess where an adversary must be positioned to execute the attack most successfully. Mitigations are presented for network operators seeking to insulate themselves from this attack.

Degree
Master of Science
Major
Computer Science
File(s)
Thumbnail Image
Name

utkirtd_11972.pdf

Size

12.35 MB

Format

Adobe PDF

Checksum (MD5)

f1e5ae9f0823e2efa952afbfd9e6f100

Built with DSpace-CRIS software - Extension maintained and optimized by 4Science

  • Privacy policy
  • End User Agreement
  • Send Feedback
  • Contact
  • Libraries at University of Tennessee, Knoxville
Repository logo COAR Notify